Bitget said Friday that attackers moved about $387.5 million out of the exchange on Thursday, raising its first estimate of $351.6 million after it counted transfers on Zcash and TRON. It said it has found and fixed the flaw the attackers used and will announce the status of withdrawals, suspended since Thursday, by midnight ET.
The attackers never needed Bitget’s private keys. CEO Gracy Chen said on X late Thursday that “the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” Bitget’s own systems, in other words, signed the transfers. Mandiant and SlowMist are helping investigate.
Friday’s update also lists an XRP Ledger address as one of the attacker’s. Unchained reported Thursday, minutes before Bitget’s first estimate, that XRP wallets labeled as Bitget’s had sent a large sum to that address, though it could not yet tie the address to the attacker.
A Familiar Playbook
The method resembles the $1.5 billion Bybit theft of February 2025, which was attributed to North Korea’s Lazarus Group. Attackers there tampered with the web interface of Bybit’s multisig wallet provider, so Bybit’s signers approved a transfer that looked routine.
Chen said Friday that “based on IP behavioral patterns and on-chain signatures, this attack is consistent with techniques used by DPRK-linked hacker groups.” Onchain analyst Specter said the stolen XRP could be linked to funds from July’s $24 million hack of AFX, which Specter said had been attributed to TraderTraitor, a North Korean group.
Where the ETH Sits
Nansen traced one branch of the stolen funds until 40,000 ETH sat divided equally among four new addresses. As of 6:34 p.m. ET Friday, those four and four other wallets on Bitget’s own list of attacker addresses held about 68,300 ETH, worth roughly $184 million, Ethereum records reviewed by Unchained show. None of the eight has ever sent a transaction.
Bitget said some stolen funds have been frozen, and it is offering 5% of any funds frozen or recovered to people whose voluntary efforts lead to a freeze or recovery, with Bybit’s LazarusBounty as one channel. On Thursday, Chen said Bitget’s User Protection Fund, which she put at more than $464 million, covers the full loss. The revised figure equals about 84% of that amount.
Related Listen: The Chopping Block: ColdCard’s $100M RNG Hack, AI-Powered Security & Ethereum’s Staking Yield Taper
